CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-4508

    Last Modified: 16 Apr 2026

    Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file.

    Published: 23 Dec 2005
    4.3
    Medium

    CVE-2005-4507

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields.

    Published: 23 Dec 2005
    7.8
    High

    CVE-2005-4504

    Last Modified: 16 Apr 2026

    The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-3536

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-3537

    Last Modified: 16 Apr 2026

    A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

    Published: 22 Dec 2005
    4.9
    Medium

    CVE-2005-3660

    Last Modified: 16 Apr 2026

    Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to finish the transfer by causing the process to become a zombie, or closing the file descriptor without closing an associated reference.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4501

    Last Modified: 16 Apr 2026

    MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4500

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-3534

    Last Modified: 16 Apr 2026

    Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4502

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-4503

    Last Modified: 16 Apr 2026

    httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4490

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4489

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4481

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. NOTE: the vendor has disputed this vulnerability, stating that the "XSS flaw was only part of the custom implementation of the [polopoly] site". As of 20061003, CVE has no further information on this issue, except that the original researcher has a history of testing live sites and assuming that discoveries indicate vulnerabilities in the associated package

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4499

    Last Modified: 16 Apr 2026

    The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4498

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4497

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4493

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4486

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news_and_events_new.asp and (2) news.asp. NOTE: on 20060227, the vendor disputed the accuracy of this report, saying that the p_news_id, news_and_events_new.asp, and news.asp are not specifically part of their product, although they could be dynamically generated through use of the product. Some investigation by CVE suggests evidence that the news_and_events_new.asp page has at least a forced invalid SQL syntax error, but this could not be repeated for news.asp

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4485

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4483

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4476

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4492

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4491

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states "This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues."

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4484

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4487

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter.

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4488

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.

    Published: 22 Dec 2005
    2.6
    Low

    CVE-2005-4494

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4495

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional research that suggests that this might be path disclosure from invalid SQL syntax

    Published: 22 Dec 2005
    4.3
    Medium

    CVE-2005-4496

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4475

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4482

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4480

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4479

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4478

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.

    Published: 22 Dec 2005
    6.8
    Medium

    CVE-2005-4477

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.

    Published: 22 Dec 2005
    5.1
    Medium

    CVE-2005-4474

    Last Modified: 16 Apr 2026

    Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose filename contains a non-default code page and non-ANSI characters, as demonstrated using a Chinese filename, possibly due to buffer expansion when using the WideCharToMultiByte API. NOTE: it is not clear whether this problem can be exploited for code execution. If not, then perhaps the user-assisted nature of the attack should exclude the issue from inclusion in CVE.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4469

    Last Modified: 16 Apr 2026

    Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4470

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4468

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY parameter.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-4467

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BASE_DIRECTORY parameter.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4466

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that contains a large number of space or tab characters.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-4471

    Last Modified: 16 Apr 2026

    POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4472

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-4473

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL."

    Published: 22 Dec 2005
    7.5
    High

    CVE-2005-4465

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 22 Dec 2005
    7.8
    High

    CVE-2005-4464

    Last Modified: 16 Apr 2026

    Ingate Firewall before 4.3.4 and SIParator before 4.3.4 allows remote attackers to cause a denial of service (kernel deadlock) by sending a SYN packet for a TCP stream, which requires an RST packet in response.

    Published: 22 Dec 2005
    5
    Medium

    CVE-2005-4463

    Last Modified: 16 Apr 2026

    WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.

    Published: 21 Dec 2005
    7.5
    High

    CVE-2005-4462

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.

    Published: 21 Dec 2005
    7.5
    High

    CVE-2005-4461

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.

    Published: 21 Dec 2005